Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ASA, conduits, ftp-data

Status
Not open for further replies.

dozier

MIS
Apr 17, 2001
88
US
Alright, a little curious about something here.

*Things are currently working, but I want to know how/why*

I have a host on the inside network that regularly initiates FTP connections to a host on the DMZ network. Doesn't the 'fixup protocol ftp 21' statement eliminate the need to expressly permit the ftp-data connection (on port 20) that originates from the ftp server on the DMZ via conduits or access-lists? Isn't that a part of the ASA? I ask because there is currently a conduit allowing TCP connections inbound back to this inside host from the ftp server on the DMZ and it is taking hits. Would these FTP connections still work if I removed the conduit?

Thanks.
 
My understanding is yes, they should still work, providing the host can make the initial port 21 connection. The traffic on port 20 should be expected and allowed by the fixup command. Why the conduit command is registering hits i couldn't say

CCNA, MCSE, Cisco Firewall specialist, VPN specialist, wannabe CCSP ;)
 
Thanks for the sanity check.

Theoretically it could be some other kind of connection that's generating the hits since the conduit is for any tcp connection, not specifically ftp. Everytime I do a 'show conn' though all I see are the ftp connections, so it looks like that is in fact what's increasing the counts.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top